Описание
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates are introduced but input verification is not done. The fault is rectified in version 1.0.0.beta.2.
Ссылки
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- ExploitPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.0 (исключая)
cpe:2.3:a:ballcat:codegen:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04696
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
CWE-20
Связанные уязвимости
CVSS3: 8.8
github
почти 4 года назад
ballcat-codegen template engine remote code execution injection
EPSS
Процентиль: 89%
0.04696
Низкий
8.8 High
CVSS3
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-94
CWE-20